Amit Avner

4.6K posts

Amit Avner banner
Amit Avner

Amit Avner

@AmitAvner

I like building stuff, with or without Lego blocks. Investing @ https://t.co/Enl1N9pdsa. Co-Founder @ Labrador Health (acquired), Founder/CEO @Taykey (acquired)

Katılım Ağustos 2008
266 Takip Edilen4.1K Takipçiler
Amit Avner
Amit Avner@AmitAvner·
סקר לשישי: שניצל בחלה הכי מומלץ בתל אביב?
עברית
5
0
7
1.4K
Vivek Gopalan
Vivek Gopalan@vvkgopalan·
Vivek Gopalan signs a $410 compute deal with Amazon
English
7
0
156
23.6K
Amit Avner
Amit Avner@AmitAvner·
@Tecnology @omerka בהקשר הזה, מצאנו באקומפליש חולשה בסנדבוקס של אנתרופיק: x.com/_orcaman/statu…
Or Hiltch@_orcaman

Introducing SharedRoot vulnerability: we recently found and reported several sandbox escape vulnerabilities to @AnthropicAI, and today we want to share one of these. I think most people don't understand the severity of the situation we are facing, with AI-assisted kernel bug-finding industrializing. Sandboxes are structurally one N-day behind, all the time, so containment can't lean on a guest Linux kernel being clean. SharedRoot enables escaping the Cowork VM (a kernel-level isolated solution, which is considered much more secure than the sandbox that ships with codex or claude code), allowing an attacker to gain unauthorized access to the user’s computer. Exploiting the SharedRoot vulnerability uncovered by the @Accomplish_ai research team, a user who is certain Cowork only has access to a specific uploaded folder on their computer - actually exposes their entire contents of their computer to an attacker leveraging the Cowork vulnerability. Read about the full technical details of the attack chain in our blog post by @orenyomtov below -->

עברית
0
0
1
263
כלכליסט-טק
כלכליסט-טק@Tecnology·
"מתקפת סוכנים חסרת תקדים": מודלים מתקדמים של OpenAI ברחו מהמעבדה תוך כדי מבחן סייבר ופרצו למערכות מחשוב calcal.ist/ycksf4w6 @omerka
כלכליסט-טק tweet media
עברית
2
1
1
786
Or Hiltch
Or Hiltch@_orcaman·
Introducing SharedRoot vulnerability: we recently found and reported several sandbox escape vulnerabilities to @AnthropicAI, and today we want to share one of these. I think most people don't understand the severity of the situation we are facing, with AI-assisted kernel bug-finding industrializing. Sandboxes are structurally one N-day behind, all the time, so containment can't lean on a guest Linux kernel being clean. SharedRoot enables escaping the Cowork VM (a kernel-level isolated solution, which is considered much more secure than the sandbox that ships with codex or claude code), allowing an attacker to gain unauthorized access to the user’s computer. Exploiting the SharedRoot vulnerability uncovered by the @Accomplish_ai research team, a user who is certain Cowork only has access to a specific uploaded folder on their computer - actually exposes their entire contents of their computer to an attacker leveraging the Cowork vulnerability. Read about the full technical details of the attack chain in our blog post by @orenyomtov below -->
Or Hiltch tweet mediaOr Hiltch tweet media
Sam Altman@sama

we had a significant security incident during evaluation of our models. we are sharing what we have learned so far. thanks to @huggingface for the partnership on this. openai.com/index/hugging-…

English
20
34
250
46K
Amit Avner
Amit Avner@AmitAvner·
אם אתם עוקבים אחרי @_orcaman אתם יודעים כבר שמצאנו חולשה מעניינת בסנדבוקס של אנתרופיק. אבל בשולי הדברים, איזה יפה העיצוב של הבלוג שלנו: accomplish.ai/blog/sharedroo…
עברית
2
1
34
2K
Amit Avner
Amit Avner@AmitAvner·
Our research team discovered sandbox vulnerability in Anthropic's Cowork, worth a read.
Or Hiltch@_orcaman

Introducing SharedRoot vulnerability: we recently found and reported several sandbox escape vulnerabilities to @AnthropicAI, and today we want to share one of these. I think most people don't understand the severity of the situation we are facing, with AI-assisted kernel bug-finding industrializing. Sandboxes are structurally one N-day behind, all the time, so containment can't lean on a guest Linux kernel being clean. SharedRoot enables escaping the Cowork VM (a kernel-level isolated solution, which is considered much more secure than the sandbox that ships with codex or claude code), allowing an attacker to gain unauthorized access to the user’s computer. Exploiting the SharedRoot vulnerability uncovered by the @Accomplish_ai research team, a user who is certain Cowork only has access to a specific uploaded folder on their computer - actually exposes their entire contents of their computer to an attacker leveraging the Cowork vulnerability. Read about the full technical details of the attack chain in our blog post by @orenyomtov below -->

English
0
0
10
618
Amit Avner
Amit Avner@AmitAvner·
@Tecnology @omerka בהקשר הזה, מצאנו באקומפליש חולשה בסנדבוקס של אנתרופיק: x.com/_orcaman/statu…
Or Hiltch@_orcaman

Introducing SharedRoot vulnerability: we recently found and reported several sandbox escape vulnerabilities to @AnthropicAI, and today we want to share one of these. I think most people don't understand the severity of the situation we are facing, with AI-assisted kernel bug-finding industrializing. Sandboxes are structurally one N-day behind, all the time, so containment can't lean on a guest Linux kernel being clean. SharedRoot enables escaping the Cowork VM (a kernel-level isolated solution, which is considered much more secure than the sandbox that ships with codex or claude code), allowing an attacker to gain unauthorized access to the user’s computer. Exploiting the SharedRoot vulnerability uncovered by the @Accomplish_ai research team, a user who is certain Cowork only has access to a specific uploaded folder on their computer - actually exposes their entire contents of their computer to an attacker leveraging the Cowork vulnerability. Read about the full technical details of the attack chain in our blog post by @orenyomtov below -->

עברית
0
0
5
187
Amit Avner
Amit Avner@AmitAvner·
Should I launch a router-router to route between all the new model routers launched this week?
English
2
0
9
750
Nim Ravid
Nim Ravid@Nim_Ravid1·
Introducing Aidan, your newest AI employee Aidan is the first computer-using AI built for realtime conversation We’ve raised $45M from @sequoia and @8VC to bring Aidan to the world @NotionHQ and @DecagonAI already use Aidan to run customer interactions. This is how @withsableai works:
English
303
142
1.5K
714.8K
Amit Avner
Amit Avner@AmitAvner·
@amitaiz כבר הייתה בעבר גלידריה מול הגינה (אאל״ט איפה שהיום נמצא גרינברג המבורגר), אבל לא הצליחה
עברית
1
0
2
90
Amitai Ziv
Amitai Ziv@amitaiz·
הגיע הזמן. פותחים גלידריה על שינקין. מתחת שורצקי. חדשות השכונה.
עברית
6
0
18
1.7K
Amit Avner
Amit Avner@AmitAvner·
@Dean_La הדרישות שלך די דומות לדרישות שלי, אבל אני גם חייב את הרצועה שמחברת תיק למזוודה ("להלביש" את התיק גב על הידית של המזוודה). אני כבר מלא שנים עם Tumi גם כל פעם שהיו לו תקלות הם טיפלו, החליפו וסידרו.
עברית
1
0
1
859
Dean Langsam
Dean Langsam@Dean_La·
התיק שלי מתקרב לסוף ימיו. אני רוצה המלצות לתיק חדש. אבל יש לי דרישות ברמת מנהל מוצר עם יותר מדי זמן פנוי בג'ירה. אתם לא חייבים להמליץ, אבל אם כן, אז תשתדלו בגבולות גזרה. אני מחפש תחליף לתיק Samsonite Kombi Small שלי. מה אני כן רוצה: - תיק יומי למשרד / נסיעות קצרות, עם פרופיל (יעני סילוהט) קומפקטי - קטן מ-23 ליטר, כי כבר יש לי תיק גדול יותר שאני אוהב למקרים שבהם אני צריך יותר מקום (דקתלון אסקייפ 500 המפתיע לטובה) - שיכיל את הלפטופ 16" שלי בפועל, גם אם לא רשמית. הקומבי הוא רשמית 15" אבל מכניס את המ5 מקס 16" בסדר גמור - הרבה “יחידות לוגיות”, כלומר מקומות נפרדים וברורים לדברים, למשל תא רשת עם ריצ׳רץ׳ בתוך תא גדול, כיס פנימי קטן, חוצצים, שרוולים, או ארגונית פנימית - תא ייעודי ללפטופ, תא ראשי, ותא משני / ארגונית - כיסים קטנים חיצוניים לדברים שצריך לשלוף מהר - מראה נקי, דק, ולא מגושם אני ממש לא רוצה: - תא ראשי אחד גדול וריק כמו בדגמים הפופולריים של טופו או הרשל. הם אכן יפים, אבל לא פונקציונליים לי. - תיקים שהם “שק עם כתפיות” - רולטופ / תיק עם flap / סגירת שרוך - תיקי לייף סטייל מינימליסטיים בלי ארגון אמיתי - כל דבר באזור 23 ליטר ומעלה.
Dean Langsam tweet media
עברית
89
2
164
74.3K
Amit Avner
Amit Avner@AmitAvner·
למה בGett שהנוסע מבטל נסיעה הוא משלם קנס אבל שהנהג מבטל נסיעה הנוסע לא מקבל פיצוי?
עברית
41
10
1.7K
59.9K
Amit Avner
Amit Avner@AmitAvner·
לומדים הרבה על אנשים מהזימונים שהם שולחים והפורמט שלהם. למשל: לשלוח זימון של: <FirstName1> + <FirstName2> כמה שבועות קדימה זאת הנחה מעניינת של הצד השולח שכולם יזכרו מי זה מי ומה סיבת הפגישה.
עברית
3
0
6
847
Amit Avner
Amit Avner@AmitAvner·
Amit: "Excuse, how do I get to the bathroom?* Waiter: "Just take the elevator one floor down." The elevator:
Amit Avner tweet media
English
0
0
1
395